CVE-2026-107696: FFmpeg through 9.0.2 Infinite Loop via RTSP Redirect Handling in rtsp.c
FFmpeg through 9.0.2 contains an infinite loop vulnerability in ffrtspconnect() in libavformat/rtsp.c that follows RTSP 3xx redirects without any redirect limit. Attackers controlling an RTSP server can answer every request with a 302 redirect to itself or another server, causing endless reconnects that saturate a CPU core.
Affected Software
Event History
Frequently Asked Questions
Which deployments are most exposed?
Deployments using FFmpeg through 9.0.2 that connect to RTSP servers controlled by untrusted parties are exposed. An RTSP endpoint under attacker control can keep the client reconnecting indefinitely.
What does an attacker need to do to trigger the issue?
The attacker needs control of an RTSP server that FFmpeg connects to. The server can respond to each request with a 302 redirect back to itself or to another attacker-controlled server.
What operational symptoms indicate exploitation?
Affected FFmpeg processing may repeatedly reconnect through RTSP redirects and enter an endless loop. This can saturate a CPU core and cause availability impact.